Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

LinkedIn has a solid security team today. That was probably not the case when this breach apparently happened, though. Just because the dump leaked today has SHA-1 hashes, doesn't mean that's what they're doing now.


They should have never been doing that. And they regardless of what team they have, they have a terrible perception.


I'm not invested in changing your opinion of LinkedIn. I'm not a fan either. I'm just clarifying that the team there now didn't have anything to do with what happened in (apparently) 2012, and I would not count on your assumptions of what they're doing with passwords as being valid anymore.


Even that few years ago, the percentage of companies doing exactly that was pretty large. The message about bcrypt has in fact made its mark.


No, a "solid security team" doesn't wait 4 years to do password resets, nor do they let people use their personal emails for work repos.

"There are no experts, only various levels of incompetence" ;)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: